Desk live·
ForensicPost
Cloud/Exploitation/File 25-0719

ToolShell SharePoint Chain Confirmed Under Exploitation, 150 Organisations Hit

The ToolShell chain against on-premises SharePoint was identified on 18 July 2025 and confirmed under active exploitation on 19 July. Around 150 organisations were reached.

Constructed geometry · not a chart of case data
TargetOn-premises SharePoint estates
ActorMultiple
D. Kennedy12 min readConfidence: high3 sources reviewed

An exploit chain designated ToolShell, combining CVE-2025-53770 and CVE-2025-53771, was used against internet-facing on-premises Microsoft SharePoint servers to achieve remote code execution and steal cryptographic material. The chain was identified on 18 July 2025 and confirmed under active exploitation on 19 July. Reporting places around 150 organisations among those reached.

Microsoft attributed activity to China-aligned intrusion sets it tracks as Linen Typhoon and Violet Typhoon, and to a third cluster designated Storm-2603 which deployed ransomware.

On-Premises, Which Is The Whole Point

The hosted version of the product was not affected in the same way. The organisations compromised were those running the software themselves — frequently for the reasons that most often justify it: regulatory requirements, data residency, integration with systems that cannot move, or a judgement that self-hosting is more secure.

What self-hosting actually transfers is the patch obligation. A hosted service is remediated by the vendor across every tenant simultaneously; an on-premises estate is remediated by whoever is available, at whatever pace their change process permits. In a window measured in days, that difference decides the outcome.

This desk does not read that as an argument for hosted services generally — the concentration files throughout this corpus record what happens when everyone depends on one provider. It is an argument that the trade has two sides and only one of them is usually counted.

Three Actors, One Chain, Different Objectives

Two of the named clusters are assessed as espionage operations. The third deployed ransomware. The same exploit chain served collection and extortion within days of each other.

That is worth recording because the corpus organises itself by actor motive — nation-state, ransomware, criminal — and this file demonstrates that the categories describe intent rather than capability. A working exploit is available to anyone who obtains it, and the defensive question is identical regardless of who arrives.

A Document Store Is A Document Store

SharePoint holds the material an organisation writes down: contracts, board papers, incident reports, personnel matters, engineering documentation. It is not a database of customer records and it does not generate a notification with an affected count.

For an espionage operation it is a better target than a customer database, and it is the category the breach registers do not capture — the same measurement gap filed at 25-1204 for manufacturing intellectual property.

How we reported this

Compiled from vendor advisories and public research, listed below. Attribution follows Microsoft’s published assessment as reported. The 150 figure is a reported count of identified victims and should be read as a floor. Corrections: corrections@forensicpost.com.

Sources
  1. ToolShell campaign: new SharePoint zero-day CVE-2025-53770SOCRadar
  2. ToolShell exploit chain puts thousands of SharePoint servers at riskRecorded Future
  3. Inside the ToolShell campaignFortiGuard Labs
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary